2009•Unpublished venueRequires access

Computer system security model based on system call related to security

Jimin Li, Zhen Li, Kunlun Li

Open publisher page 0 citations

Abstract

A computer system security model based on system call related to security is proposed. It is inspired from the biological immune system and overcomes some drawbacks of traditional computer immune system based on system call. It makes the number of system calls intercepted decrease significantly, records the arguments of system call which are useful information for intrusion detection without low efficiency, and distinguishes non-self from self by Sandbox as well as rule matching. Furthermore, our model resolves the unreliability and insecurity of process and the display of process behavior incompletely caused by denying the execution of a system call in traditional Sandbox systems. Experimental results show that different non-self class can be distinguished accurately and non-self can be detected in Sandbox which is unknown type by rule matching without imposing heavy performance impact upon operating system.

About this research paper

What this paper is about

A computer system security model based on system call related to security is proposed. It is inspired from the biological immune system and overcomes some drawbacks of traditional computer immune system based on system call. It makes the number of system calls intercepted decrease significantly, records the arguments of system call which are useful information for intrusion detection without low efficiency, and distinguishes non-self from self by Sandbox as well as rule matching. Furthermore, our model resolves the unreliability and insecurity of process and the display of process behavior incompletely caused by denying the execution of a system call in traditional Sandbox systems. Experimental results show that different non-self class can be distinguished accurately and non-self can be detected in Sandbox which is unknown type by rule matching without imposing heavy performance impact upon operating system.

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

A computer system security model based on system call related to security is proposed. It is inspired from the biological immune system and overcomes some drawbacks of traditional computer immune system based on system call. It makes the number of system calls intercepted decrease significantly, records the arguments of system call which are useful information for intrusion detection without low efficiency, and distinguishes non-self from self by Sandbox as well as rule matching. Furthermore, our model resolves the unreliability and insecurity of process and the display of process behavior incompletely caused by denying the execution of a system call in traditional Sandbox systems. Experimental results show that different non-self class can be distinguished accurately and non-self can be detected in Sandbox which is unknown type by rule matching without imposing heavy performance impact upon operating system.

Key concepts: Sandbox (software development), System call, Computer science, Intrusion detection system, Process (computing), Computer security, Matching (statistics), Computer security model

Related papers

Back to paper searchBrowse research topicsOriginal source
Computer system security model based on system call related to security — Research Paper | ScholarLens